CVE-2014-0056
OpenStack Neutron Improper Authentication vulnerability
EPSS 1.4%
描述
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.
如何修補 CVE-2014-0056
要修補 CVE-2014-0056,請將受影響套件升級到下列已修補版本。
- PyPI/neutron—升級至 2013.2.3 或更新版本
- PyPI/neutron—升級至 2013.2.3 或更新版本
CVE-2014-0056 正在被利用嗎?
低 — EPSS 為 1.4%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 2012.2, < 2013.2.3
- >= 2012.2, < 2013.2.3